$ cat writeup.md…
$ cat writeup.md…
tjctf
Task: Next.js App Router chat app using vulnerable React 19.x Server Components. Solution: Exploit REDACTED (React2Shell) for RCE, then extract the flag from .env in git commit history.
$ cat /etc/rate-limit
Rate limit reached (20 reads/hour per IP). Showing preview only — full content returns at the next hour roll-over.
i vibe coded a website and told gpt to make it secure so there is nothing you can do now!!!
English summary: A Next.js App Router chat application ("yap") where users can register, login, and post messages. Built with React Server Components on React 19.x. The developer claims it was "vibe coded" (AI-generated) and secured by GPT. The goal is to find the flag hidden on the server.
5VGptBeLn4iPBWXBhhT5c)/var/lib/yap/data.dbyap_user=<username> (HttpOnly, plain text)/Login: 40cecd84ea8f6a2e4fc21505453351fd6313e28428
Register: 40ed6c0b53c7f99c3fa4946ff1d02a94a11906dcc9
Post yap: 401f68b86df260cd0037fbe5c9a5c671a3920b1f78
Logout: 000791216483786dde7eac56bee8877a5a2f9b928d
User 'zain' had a welcome message: "Welcome to the yap chat app! This is a pretty cool chat app 100% made by humans. Source: true me bro."
The application uses a vulnerable version of React (19.0.0–19.2.x) with React Server Components. CVE-2025-55182 is a critical Remote Code Execution vulnerability that allows an attacker to execute arbitrary code on the server by sending specially crafted HTTP requests to Server Function endpoints via the RSC Flight protocol.
Related CVEs in the same family:
References:
...
$ grep --similar